Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Fix for CVE-2026-6067 .

Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0

Fixes CVE-2026-41565

Multiple security vulnerabilities have been discovered in Tomcat 9, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. In order to address certain vulnerabilities and restore the compatibility with Tomcat 9, an upgrade of the Tomcat native library, libtcnative-1, […]

https://security-tracker.debian.org/tracker/DSA-6325-1

https://security-tracker.debian.org/tracker/DSA-6326-1

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 8 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable distribution (bookworm), these problems have been fixed

It was discovered that incorrect cookie header accounting in the HTTP/2 implementation of the Apache HTTP server may result in denial of service (excessive resources consumption). For the oldstable distribution (bookworm), this problem has been fixed in version 2.4.67-1~deb12u3.

It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-4+deb11u2. We recommend that you upgrade your gsasl packages.

An update that solves 23 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities and has five fixes can now be installed.

Security update

Security update

Update to latest upstream version.

New upstream release (151.0.3)

Add support for half-width fonts. Improve content filter compilation by avoiding file copies. Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. Fix painting scrollbars when their width changes.

libinput 1.31.3, fixes a udev property inject via uinput devices that can lead to local privilege escalation

Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs

An update that contains security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6323-1

https://security-tracker.debian.org/tracker/DSA-6324-1

Security update

Security update

Security update

Security update

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves 19 vulnerabilities and has 7 bug fixes can now be installed.

An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.

An update that solves 11 vulnerabilities and has 12 bug fixes can now be installed.

————————————————————-

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 7 vulnerabilities can now be installed.

An update that solves 7 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 7 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves 5 vulnerabilities can now be installed.

New libinput packages are available for Slackware 15.0 and -current to fix a security issue.

New dnsmasq packages are available for Slackware 15.0 and -current to fix a security issue.

How to Harden SSH on Linux After Disabling Password Authentication

YARD could be made to expose sensitive information over the network.

Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1.

Beyond automation: Why the surge in AI-driven security vulnerabilities demands human technical advocacy
Fragnesia and friends: When page cache vulnerabilities keep coming back
The Role of Natural Language Processing in Detecting Phishing Emails

Warisjeet Singh discovered that Exim, a mail transport agent, does not properly handle PROXY frames whose declared payload length is too short for the claimed address family, which may result in information disclosure in configurations with SUPPORT_PROXY and ‘host_proxy’ set. For Debian 11 bullseye, this problem has been fixed in version

Postfix could be made to crash if it received specially crafted network traffic.

Several security issues were fixed in Robocode.

Several security issues were fixed in Exim.

Several security issues were fixed in Tomcat.

4.1.2, fix for CVE-2026-38978

libre v4.8.1 (2026-05-28) fmt/pl: add pl_strip_html() sys/fs: add getpwuid fallback for fs_gethome tls: remove unused include rsa.h ice: check source address of incoming application packets

33.0.4 Release

Backport fix for CVE-2026-48710

This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)

Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

4.1.2, fix for CVE-2026-38978

Update to Samba 4.23.8 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238